US8554930B2

Method and system for proof-of-possession operations associated with authentication assertions in a heterogeneous federated environment

Summary by NHIP

Proof-of-possession authentication method

The method processes user assertions across federated domains by challenging clients to prove possession of required information before validating access requests. A second trust proxy sends a request for challenge information to a first trust proxy, generates the specific challenge, and validates the user's response to confirm identity before accepting the original assertion.

Claim Score by NHIP

Read claim 1, the broadest

Abstract

A method, apparatus, system, and computer program product are presented in which federated domains interact within a federated environment. Domains within a federation are able to initiate federated single-sign-on operations for a user at other federated domains. A point-of-contact server within a domain relies upon a trust proxy within the domain to manage trust relationships between the domain and the federation. Trust proxies interpret assertions from other federated domains as necessary. Trust proxies may have a trust relationship with one or more trust brokers, and a trust proxy may rely upon a trust broker for assistance in interpreting assertions. To enhance security, domains may also require users to re-prove their identity through proof-of-possession challenges that are executed after a user has initiated a single-sign-on operation.

US8554930B2, drawing sheet 1
Sheet 1 of 11

Term

Projected expiry 3 March 2029.

  1. Priority and filed
  2. Granted
  3. Today
  4. Projected expiry

36 claims: 3 independent, 33 dependent

  1. 1
    Broadest claimClaim Score 49, average(NHIP)A method for assertion processing within a data processing system, the method comprising:receiving, from a first trust proxy within a first domain at a second trust proxy in a second domain, an assertion associated with a user, wherein the assertion is associated with a request from a client to access a controlled resource within the second domain;responsive to receipt of the assertion, challenging a user of the client to provide information that is required to be possessed by the user that is associated with the assertion, wherein the challenging step is performed to enable the user associated with the assertion to attempt to re-prove an identity and comprises: sending from the second trust proxy to the first trust proxy a request for challenge information;receiving the challenge information at the second trust proxy from the first trust proxy;generating a proof-of-possession challenge at the second trust proxy, wherein a valid response to the proof-of-possession challenge comprises the information that is required to be possessed by the user that is associated with the assertion;sending the proof-of-possession challenge to the client;and validating a response to the proof-of-possession challenge;and in response to a determination that the user of the client possesses the information that is required to be possessed by the user that is associated with the assertion, validating the assertion at the second trust proxy.
  2. 13
    An apparatus for assertion processing within a data processing system, the apparatus comprising:a processor;a computer memory holding computer program instructions which when executed by the processor perform a method comprising: receiving, from a first trust proxy within a first domain at a second trust proxy in a second domain, an assertion associated with a user, wherein the assertion is associated with a request from a client to access a controlled resource within the second domain;responsive to receipt of the assertion, challenging a user of the client to provide information that is required to be possessed by the user that is associated with the assertion, wherein the challenging step is performed to enable the user associated with the assertion to attempt to re-prove an identity and comprises: sending from the second trust proxy to the first trust proxy a request for challenge information;receiving the challenge information at the second trust proxy from the first trust proxy;generating a proof-of-possession challenge at the second trust proxy, wherein a valid response to the proof-of-possession challenge comprises the information that is required to be possessed by the user that is associated with the assertion;sending the proof-of-possession challenge to the client;and validating a response to the proof-of-possession challenge;and validating the assertion at the second trust proxy in response to a determination that the user of the client possesses the information that is required to be possessed by the user that is associated with the assertion.
  3. 25
    A computer program product in a computer readable medium for use in a data processing system for assertion processing, the computer program product holding computer program instructions which when executed by the data processing system perform a method comprising:receiving, from a first trust proxy within a first domain at a second trust proxy in a second domain, an assertion associated with a user, wherein the assertion is associated with a request from a client to access a controlled resource within the second domain;responsive to receipt of the assertion, challenging a user of the client to provide information that is required to be possessed by the user that is associated with the assertion, wherein the challenging step is performed to enable the user associated with the assertion to attempt to re-prove an identity and comprises: sending from the second trust proxy to the first trust proxy a request for challenge information;receiving the challenge information at the second trust proxy from the first trust proxy;generating a proof-of-possession challenge at the second trust proxy, wherein a valid response to the proof-of-possession challenge comprises the information that is required to be possessed by the user that is associated with the assertion;sending the proof-of-possession challenge to the client;and validating a response to the proof-of-possession challenge;and validating the assertion at the second trust proxy in response to a determination that the user of the client possesses the information that is required to be possessed by the user that is associated with the assertion.